Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

How-to · Beginner · 15 minutes

How to Enable Two-Factor Authentication

Make a stolen password useless on every login that actually matters — a practical, jargon-free walkthrough with the classic mistake flagged before you make it.

Straight answer first

The job: make a stolen password useless on every login that actually matters. Time to allow: 15 minutes. Skill needed: beginner.

The walkthrough below covers every step, the mistake most people make, and the shortcut worth keeping. On Hosting Seller plans several of these steps are already done for you, and we say where.

Written by the Hosting Seller staff · Checked 1 August 2026

Beginner

Difficulty level

15 minutes

Time to allow

5

Stages

24/7

Help at any hour

You do not need to be technical for this. The walkthrough is written for first-timers, tested on our own platform, and honest about which parts are genuinely fiddly and which are merely unfamiliar.

Rule of the road: read the snag section before you begin rather than after. It is harvested from the tickets of people who did it the other way round.

The overview before the detail

The job breaks into a few clear stages: pick an authenticator app, turn it on in the client area, turn it on in cpanel too, file the recovery codes now and cover the other logins as well.

No stage needs code or a terminal unless the guide says so outright, and where it does, the exact commands are printed. The full step-by-step sits below; the sections around it give the context that makes it stick.

Where this goes wrong, and how not to

Turning two-factor on and skipping the recovery codes. A lost or wiped phone then locks you out of your own protection, and a security feature turns into a support ticket with identity checks attached.

It is worth learning because it is not some rare edge case — it is the single most common reason this task turns into a support ticket. Knowing it up front turns the whole job from risky into routine.

The tip we hand out to everybody

Move the authenticator across before you wipe an old phone. The app can export its secrets, and two minutes of foresight saves you re-enrolling every account you own from scratch.

It costs a minute now and pays that back every time the job comes round again — which, like most hosting jobs, it certainly will.

What you can skip on a Hosting Seller plan

Several steps in this guide exist only because hosting historically made you do them. On our plans SSL issues itself, backups run daily without being asked, and one-click installers replace the manual setup entirely. What is left is the part that is genuinely yours.

And when a step misbehaves anyway, support answers at any hour with the actual fix, not a knowledge-base link and a shrug. Half our best guides began life as a pattern in the ticket queue.

A shield icon standing in for site security and DDoS filtering

The hosting this guide is written against

Every walkthrough on our how-to shelf is tested on the platform we actually run — cPanel, LiteSpeed, NVMe, one-click installs — so the instructions match your screen instead of gesturing vaguely at it.

What you pay on day one is what you pay at renewal, so the year-two invoice holds no surprises worth opening early.

  • Step by step, tested exactly as printed
  • The snag flagged before you reach it
  • The dull steps are already automated
  • People on hand at any hour if you stall

Why Hosting Seller

On every plan, as standard

5 steps, no filler

Each stage is a few minutes of steady clicking, with the fiddly parts marked as fiddly.

The snag, named early

The classic mistake for this exact job is flagged before step one, so 15 minutes stays 15 minutes.

Written from real tickets

Our guides come off the support desk, so the snags flagged here are the ones people genuinely hit.

Help on the counter

Stuck on step three at midnight? Support answers at any hour, mid-guide included.

Works exactly as written

Every step tested on the platform we run — no 'your host may differ' hand-waving anywhere.

The undo is always named

Where a step could bite, the guide says so and tells you how to put it back again.

First Steps

From choosing to live

  1. 1

    Pick an authenticator app

    Any TOTP app will do — Aegis, Google Authenticator, 1Password. App codes beat SMS, which can be defeated by an attacker getting your phone number ported away.

  2. 2

    Turn it on in the client area

    Security settings, scan the QR code into the app, confirm with a code. The billing account controls services and domains, so that is the one to protect first.

  3. 3

    Turn it on in cPanel too

    The panel has its own Two-Factor Authentication feature and the same short ritual. Panel access can change anything you host, so it earns an enrolment of its own.

  4. 4

    File the recovery codes now

    The backup codes shown during setup go into your password manager. They are the answer to a lost phone, and setup is the only time you will ever be offered them.

  5. 5

    Cover the other logins as well

    WordPress admin, the registrar if your domains live elsewhere, and the mailbox that can reset all of it. Two-factor gets more valuable the more of that chain it covers.

In the Box

Packed with every plan

  • Staging copies so changes get tested before they go live
  • One-click installs for WordPress and 400+ other applications
  • LiteSpeed caching running at the server, not bolted on by plugin
  • DDoS filtering handled out at the network edge
  • A backup taken daily, with restores you run yourself
  • Upgrades apply to the account in place, with no move between plans
  • PHP versions picked per site from the panel
  • Spam and virus filtering fitted to every mailbox
  • WebP image optimisation built in and costing nothing
  • WordPress Toolkit, with updates applied for you

Across the Counter

The questions we get asked most

Do I need this for a small site nobody targets?

It is the best-value minute in security. Credential leaks are constant and entirely automated, and two-factor turns every leaked password from an incident into a non-event. The test is not how big you are; it is whether you would mind losing it.

What happens if I lose the phone?

The recovery codes you saved at setup get you back in, and you enrol the new device from there. Without them, support can verify who you are and reset it — slower on purpose, because that same door is the one an attacker would knock on.

Is the SSL certificate genuinely free?

On every plan, with nothing held back. The certificate is issued the moment your domain points here and reissues itself well before expiry. The encryption is the same as a paid DV certificate — paid tiers exist only for wildcard coverage or organisation validation, which most sites never need.

Can I test changes somewhere safe first?

Yes — plans with staging let you clone the live site, work on the copy, then push it across when you are satisfied. It is the difference between hoping an update behaves and knowing that it does before any customer meets it.

Does the price climb when the term is up?

No. What you pay to order is what you pay to renew, year after year. We do not run teaser rates, so there is no year-two ambush waiting in the calendar, and your bookkeeping can treat the hosting line as a fixed number.

Can I set the PHP version myself?

Yes — PHP versions are chosen per site from the control panel, so an old application and a current one can sit side by side on the same account. Extensions and per-site settings live in the same screen, and none of it needs a support ticket.

Are backups included, and can I put one back myself?

A backup is taken daily on every plan, and the restore is yours to run from the panel in minutes — files, databases or both, at three in the morning without waiting on a ticket. Keeping your own copy offsite as well is never a bad habit, and nothing here stops you.

Packing up and moving host? Take our checklist.

A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.

One email carrying the checklist, then the odd note on running a site well. Step off the list whenever you like — our privacy policy spells out the rest.

Start on a plan with a plain price tag.

Every plan carries the essentials other hosts ring up as extras — and support that actually replies.

See the plans